Medium severity4.9NVD Advisory· Published Oct 13, 2019· Updated Jun 17, 2026
CVE-2019-17536
CVE-2019-17536
Description
Gila CMS through 1.11.4 allows Unrestricted Upload of a File with a Dangerous Type via the moveAction function in core/controllers/fm.php. The attacker needs to use admin/media_upload and fm/move.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- Gila CMS/Gila CMSdescription
Patches
Vulnerability mechanics
References
2- github.com/GilaCMS/gila/pull/49nvdExploitThird Party Advisory
- rastating.github.io/gila-cms-upload-filter-bypass-and-rce/nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.